Description
An empty password for an account that requires password authentication may cause a connection failure or weaken identity verification if the server accepts it. Passing an empty string does not mean anyone can connect. Actual access depends on the server’s authentication method, permitted clients and account permissions. Distinguish this from intentional passwordless authentication using certificates or an external identity provider.
Potential impact
- Data exposure or modification: If the server accepts the empty password, the account’s permissions may allow data to be read, changed or deleted.
- Administrative misuse: Administrative permissions may extend the impact to configuration changes and other privileged operations.
Remediation
- Set a strong password for accounts using password authentication and reject empty passwords on the server. If another authentication method is intended, verify the server and driver settings.
- Keep passwords out of code. Supply them through a secret store such as HashiCorp Vault or a restricted execution environment. KMS manages encryption keys and must be distinguished from the system that stores and retrieves secrets.
- Minimize account permissions and network access. For remote connections, configure TLS with server-certificate verification.
Examples
Before
java
import java.sql.Connection;
import java.sql.DriverManager;
import java.sql.SQLException;
public class InsecureDBConnection {
public static void main(String[] args) throws SQLException {
String url = "jdbc:mysql://localhost:3306/mydb";
String user = "root";
String password = ""; // Empty password
Connection conn = DriverManager.getConnection(url, user, password);
}
}
After
java
import java.sql.Connection;
import java.sql.DriverManager;
import java.sql.SQLException;
public class SecureDBConnection {
public static void main(String[] args) throws SQLException {
String url = "jdbc:mysql://localhost:3306/mydb";
String user = System.getenv("DB_USER"); // Load from the environment.
String password = System.getenv("DB_PASSWORD");
if (password == null || password.isEmpty()) {
throw new SecurityException("Database password is not set");
}
Connection conn = DriverManager.getConnection(url, user, password);
}
}
Explanation:
- Before: Passes an empty password for
root. Whether the connection succeeds depends on the database server settings. - After: Reads the account and password from environment variables and stops if the password is absent or empty. Environment variables alone do not protect a secret; restrict access to the runtime environment and logs. Connection cleanup and driver-specific TLS configuration are omitted.